CVE-2014-3906: Kk-Osk Advance-Flow

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected products

  • Kk-Osk Advance-Flow: up to and including 4.41
  • Kk-Osk Advance-Flow Forms: up to and including 4.41

Published 2014-08-19. Last modified 2026-06-17.